Payments secured by Stripe — PCI DSS Level 1
Card numbers never touch Dinify's servers. We store only the card brand and last 4 digits for display.
Dinify is designed to protect your restaurant's and your guests' data at every layer.
Card numbers never touch Dinify's servers. We store only the card brand and last 4 digits for display.
Traffic between you and Dinify is encrypted, with HSTS to keep it that way.
Aligned with PIPEDA, GDPR, CCPA and Québec Law 25.
Express and implied consent, with one-click unsubscribe on every message.
Each restaurant's data is walled off, with least-privilege roles per team member.
Sensitive actions are recorded so there's a trail of who did what.
All traffic runs over TLS 1.2 or higher, with HSTS to prevent downgrade.
Passwords are hashed with bcrypt, sessions use short-lived JWTs, and repeated failed logins trigger brute-force lockout.
Sensitive endpoints are rate-limited to blunt abuse and automated attacks.
Requests are validated and sanitised, with protection against NoSQL injection.
Role-based access control means staff only see and do what their role allows.
Each restaurant's data is isolated per tenant, so one restaurant can't reach another's.
Authentication and money-affecting actions are written to append-only audit logs.
Diners pay into the restaurant's own Stripe account. Dinify never holds card data — card numbers never touch our servers. Stripe is certified PCI DSS Level 1, the highest level of payment-card security.
Guests can access, export or delete their data — self-service in the Dinify diner app, or by emailing info@dinify.ca. Restaurants can request their data per our Data Processing Agreement. See our Privacy Policy.
The trusted providers we use to run Dinify, and what each does.
| Subprocessor | Purpose |
|---|---|
| Stripe | Payments |
| Twilio | SMS / OTP |
| Amazon Web Services | Hosting, storage and email |
| Cloudflare | CDN and DNS |
| Fly.io | App hosting |
| MongoDB Atlas | Database |
| Google Firebase | Phone verification |
| Google Maps | Location |
| Anthropic | AI features — processes menu text and diner chat |
| SendGrid |
Legacy providers no longer used for new processing: Razorpay, Clover. See our Data Processing Agreement for details and contractual safeguards (SCCs).
We align our controls to SOC 2 and ISO/IEC 27001 principles. A SOC 2 Type II examination is on our roadmap; we will publish the report here once complete.
Found a vulnerability? Email info@dinify.ca. See our security.txt.
Start free — no credit card, no hardware, no lock-in. Or book a demo and we'll walk you through how your data is kept safe.